Sunday, April 12, 2009

European Commission position on anonymisers

European law requires data retention - tracking details of every email you send. But data retention is easily circumvented by using anonymous email services. So will European law eventually prohibit anonymous email as well?

Jens Holm MEP recently put down a question on this issue. Here's the text of his question and the Commission's rather lukewarm response - while anonymisers might not be under threat at European level at the moment, the answer suggests that this might change in the not too distant future:
Anonymity services

The need for reliable systems for giving information anonymously has been highlighted in connection with trials concerning serious criminal cases and financial crime. Large sums can be lost if ordinary members of the public do not dare to contact journalists or the police. The development of electronic anonymity services has come a long way in Sweden. They are used by both private individuals and companies, on both the Internet and intranets, for both private and commercial use.

1. Does the Commission intend to submit a proposal to prohibit such services within certain fields?

2. Does the Commission consider that individual Member States have the right to prohibit such services?

3. Does the Commission consider that the right to electronic anonymity is or should be guaranteed at EU level?

Answer given by Mr Barrot on behalf of the Commission (3.4.2009)

1. The Commission is studying the impact of anonymity services on the ability of law enforcement bodies to provide security to the citizens in the EU. The Commission is currently not planning to submit a proposal prohibiting the use of such services.

2. It is the Member States' responsibility to safeguard their internal security. If the use of these services demonstrably limits their ability to do so, they may consider regulating the use of these services, while respecting the European Convention on Human Rights and other principles and guarantees regarding civil liberties in Europe and their obligations under the Treaties. Any such measures must be duly justified and must be proportionate and limited to what is necessary in a democratic society. Furthermore, given the relevance of whistle blowing systems for law enforcement against certain types of crime, the need to maintain the possibility of conferring information anonymously to the relevant organisations should be taken into account when considering regulation of anonymous communications services.

3. The fundamental right to protection of personal data is enshrined in Article 8 of the EU Charter. Whilst there is no explicit right to electronic anonymity as such under Community law, the Data Protection Directive is to require that personal data must be processed fairly and lawfully, including the data minimisation principle. This principle may be furthered by the use of anonymous data wherever possible. Confidentiality of communications and related traffic data is protected by the Directive on privacy and electronic communications. The data minimisation principle, leading to anonymity, may also be achieved by the use of Privacy Enhancing Technologies (PETs). However Member States may adopt measures to restrict the scope of these principles which are necessary to safeguard important public interests such as national security or law enforcement, including combating terrorism or fighting cybercrime.

Friday, April 10, 2009

EU to require internet filtering?

One of the most important recent developments at EU level - and one that's received surprisingly little media attention (The Register aside) - is the proposal from the Commission to require member states to introduce internet filtering for child pornography. This requirement would be part of a wider Framework Decision on combating the sexual abuse, sexual exploitation of children and child pornography (PDF) and article 18 is the relevant provision:
Blocking access to websites containing child pornography
Each Member State shall take the necessary measures to enable the competent judicial or police authorities to order or similarly obtain the blocking of access by internet users to internet pages containing or disseminating child pornography, subject to adequate safeguards, in particular to ensure that the blocking is limited to what is necessary, that users are informed of the reason for the blocking and that content providers are informed of the possibility of challenging it.
In short, all European countries would be required to introduce filtering along the general lines of that coordinated by the Internet Watch Foundation in the UK (which I've described and criticised here).

The lack of detail in this proposal is worrying - what is meant by "internet pages" for example? Web pages? Usenet posts? Gopher pages? (Yes, it still exists folks - try it!) What are "adequate safeguards"? What is the difference between pages which "contain" and pages which "disseminate" child pornography? Would the ability to challenge a block include an appeal to an independent judicial authority? What sort of blocking would suffice - simple DNS poisoning, crude blocks of particular ranges of IP addresses, two-stage systems along the lines of BT's Cleanfeed?

On the other hand, in some jurisdictions (notably the UK), this proposal would represent a step forward for civil liberties. The specific safeguards proposed - decisions by "competent judicial or police authorities", blocking being limited to what is necessary, users being informed of the reason for a block and content providers being informed of a right to challenge a block - go well beyond what is currently provided for by the IWF for example. (Indeed, the Commission's impact assessment (PDF) for this proposal points out (p.30) that a system such as the IWF's which is based solely on self-regulation may not be "prescribed by law" as required by Article 10 ECHR.)

This proposal has met with strong opposition from EuroIPSA:
Malcolm Hutty, president of EuroISPA, representing ISPs from across Europe at the EU, considers the EU plans to block sites will "increase risks to the security, resilience and interoperability of the internet" and also stated: "For technical reasons, blocking simply cannot provide the level of protection that is necessary, and simple morality demands that we take strong collective action to get child pornography removed from the Internet, rather than simply hiding behind national firewalls," he added.
Incidentally, the impact assessment for the proposal contains an interesting and rather optimistic assessment of the costs associated with filtering (p.28):
In particular, blocking access to websites containing child abuse material would involve economic costs. The economic impact of a similar measure to restrict access to material inciting terrorism was assessed in revising the Council Framework Decision on Combating Terrorism. As the impact assessment accompanying the Commission proposal stated, the cost of imposing any of the different filtering methods to all internet service providers based in the EU is impossible to calculate. An upper limit of EUR 10 per computer is given on the basis of a specific example of implementing filtering in a network of 100 000 computers at 4 000 schools in Ireland. The cost of running a blacklist of illegal content may be borne by those in charge of it, whether law enforcement authorities or specific NGOs. This can be estimated at about EUR 110 000 to build the database and EUR 90 000 per year for maintenance. However, EU funding may be available for managing blacklists and exchanging information on illegal content.
The idea that the cost of generating and maintaing a blacklist can be capped at €90,000 per annum seems optimistic beyond belief. Is this supposed to include, for example, costs of compensating businesses who have been wrongfully blocked? The legal costs associated with appeals against wrongful blocks? The staff needed to look at alleged illegal content and decide whether it is in fact illegal? The effort required to keep the block list under review? By way of contrast, the overall budget for the IWF in 2006/2007 (PDF, p.15) was STG£876,087. Although not all that amount would be directed to generating and maintaining a blacklist, the figure nevertheless suggests that the Commission costs have little contact with reality.

[Edited to add: I've uploaded to SSRN a paper by Colin Scott and myself on internet filtering more generally.]

Friday, April 03, 2009

New rules for electronic discovery in Ireland

Statutory Instrument No. 93 of 2009 has made some significant changes to electronic discovery in Ireland. McCann Fitzgerald have summarised the effects:
* a party may seek electronic data in searchable form from its opponent;
* the court may order a party to give inspection and search facilities for electronic data on its computer systems to the other side;
* where computers contain sensitive non-discoverable data, the court instead may order that an independent expert carry out the inspection and search for relevant electronic data (the party seeking that discovery will have to fund the expert’s costs and expenses);
* where a party giving discovery finds that searching for the documents or data is excessively costly or burdensome, it may apply to the court to seek to narrow the scope of the discovery order;
* a party giving discovery must list the documents or data according to agreed categories or in a sequence corresponding with the manner in which the documents or data has been stored or kept in the usual course of business – the intention is to make discovery more comprehensible;
* all parties giving discovery must swear in an affidavit of discovery that they understand their obligation to give discovery of documents and electronic data (within the categories of discovery agreed or ordered by the court) which may help or damage their case in any way.
Interestingly, although the new rules provide for parties to be obliged to allow the other side "inspection and searching facilities", they appear to apply only to existing documents. They don't seem to refer to the question of whether the court can order a party to carry out analysis of ("data mine") electronic records - thus leaving unaltered the effect of the ruling in Dome Telecom v. Eircom.

Saturday, March 28, 2009

Another blow for "three strikes" and music industry internet filtering

Significant developments at European level, where the European Parliament's report Security and Fundamental Freedoms on the Internet has rejected arguments for the filtering of p2p networks or disconnection of users alleged to have shared music. As summarised by the Irish Times:
The report on security and fundamental freedom on the internet said the penalties imposed should be "proportionate to the infringements committed" and rejected "systematic monitoring and surveillance” of all users’ online activities. It also warned against "certain excessive access restrictions placed by intellectual property holders themselves".
This echoes action by the Council of Europe which in July 2008 adopted Human Rights Guidelines for Internet Service Providers. Those guidelines took a similar approach - rejecting blanket monitoring of traffic and stating that:
Cutting access to individual customer accounts constitutes a restriction on your customer’s rights to access the benefits from the information society and to exercise their rights to freedom of expression and information. Cutting access should only be done for law enforcement or other legitimate and strictly necessary reasons.
Of course, neither document is itself directly enforceable in Irish law - but both may have a persuasive effect if the issues of filtering and disconnection of users return to the High Court.

Tuesday, March 17, 2009

Censorship in Oz - Now links are banned too

Remarkable news from the Sydney Morning Herald:
The Australian communications regulator says it will fine people who hyperlink to sites on its blacklist...

The move by the Australian Communications and Media Authority comes after it threatened the host of online broadband discussion forum Whirlpool last week with a $11,000-a-day fine over a link published in its forum to another page blacklisted by ACMA - an anti-abortion website.
The irony here is that the anti-abortion website was referred to ACMA by an anti-censorship campaigner seeking to demonstrate that the blacklist would be used to censor legitimate political speech. Once he succeeded in this aim, it seems that ACMA became embarrassed by their own actions and are now trying to prevent Australians from viewing the page and deciding for themselves whether ACMA's decisions can be trusted.

Electronic Frontiers Australia has more.

In the meantime, here's the ACMA response which they're now trying to censor:
Subject: Complaint Reference: 2009000009/ ACMA-691604278
Date: Wed, 21 Jan 2009 15:45:00 +1100
From: online@acma.gov.au
Complaint Reference: 2009000009/ ACMA-691604278
I refer to the complaint that you lodged with the Australian Communications and Media Authority (ACMA) on 5th January 2009 about certain content made available at:

http://www.abortiontv.com/Pics/AbortionPictures6.htm

Following investigation of your complaint, ACMA is satisfied that the internet content is hosted outside Australia, and that the content is prohibited or potential prohibited content.

The Internet Industry Association (IIA) has a code of practice (http://www.iia.net.au/index.php?option=com_content&task=view&id=415&Itemid=33) for Internet Service Providers (ISPs) which, among other things, set out arrangements for dealing with such content. In accordance with the code, ACMA has notified the above content to the makers of IIA approved filters, for their attention and appropriate action. The code requires ISPs to make available to customers an IIA approved filter.

Information about ACMA’s role in regulating online content (including internet and mobile content), including what is prohibited or potentially prohibited content is available at ACMA’s website at www.acma.gov.au/hotline

Thank you for bringing this matter to ACMA’s attention.
One point stands out about this response. Similar to the Wikipedia debacle in the UK, material is being blacklisted on the basis that it is "potentially" prohibited - that is to say, ACMA is taking a guess as to what the actual censorship body - the Classification Board - might do if asked to decide on the material.

That link contains photos of aborted foetuses. Gruesome? Certainly. But legitimate political speech seeking to demonstrate what the site argues is the "reality" of abortion? Without a shadow of a doubt - making it remarkable that it should be banned to Australian viewers based on nothing more than a hunch as to what a censorship body might think.

Monday, March 16, 2009

Secret databases and employment blacklists

Henry Porter has been one of the most astute observers of the state of civil liberties in the UK in recent years. In this column he paints an alarming picture of how secret databases are already being abused:
The facts are horrifying. The secret database penalised innocent people by storing unverified information about character and abilities, which often prevented them gaining employment. Union membership was a black mark. An electrician from Manchester Steve Acheson believes he was blacklisted because of his union membership and only received 36 weeks employment in the last nine years. He has spoken movingly about the way his character and demeanour have been affected by the lack of work during one of the greatest construction booms ever known...

The bigger point is this: where information about people is gathered in a database without individuals knowing what is held on file or being able to challenge it if they suspect it is wrong or unjust, abuse of their rights is likely to follow. That applies right across the board – from Kerr's seedy operation, run out of anonymous offices in Droitwich, to the big government databases formed or proposed by schemes such as the national identity register, ContactPoint, the e-Borders scheme and the communications superdatabase, which will allow the government to store information on every phone call, email, text message and internet connection.

Saturday, March 14, 2009

Ryanair screen scraping case is (partially) scraped away from the Irish courts

Remember Ryanair v. Bravofly - the case brought by Ryanair in the High Court seeking to prevent Bravofly from screen scraping its website to provide users with price comparison information?

In a recent judgment, the High Court has now accepted that it has no jurisdiction over a large portion of that litigation.

The issues here are somewhat complex but to summarise: after the action against Bravofly was commenced Ryanair added a second defendant - Travelfusion - to the proceedings, on the basis that they were the "provider of the technical facilities and services necessary to permit the screen-scraping facilities".

Travelfusion, in turn, applied to have the proceedings against it dismissed on the basis that the Irish courts had no jurisdiction to hear the matter under the Brussels Regulation. This argument had two dimensions - first that as an English company with no place of business in Ireland there was no basis for jurisdiction under the Regulation and secondly that the terms of use of the Ryanair website conferred exclusive jurisdiction on the English courts. Ultimately, however, Travelfusion rested its case entirely on the second aspect.

The relevant provision was Clause 7 of the Terms of Use, which provided:
Disputes arising from the use of this website and the interpretation of these Terms of Use of the Ryanair website are governed by English Law. All disputes relating to these Term of Use and the use of the Ryanair Website are subject to the exclusive jurisdiction of the English court, save that Ryanair may, at its sole discretion, institute proceedings in the country of your domicile.
Ryanair conceded that if the clause applied it would determine jurisdiction over all the screen scraping claims - the question was, however, whether the clause took effect as part of an agreement between the parties.

This put Ryanair in a difficult and awkward position. Their claim that screen scraping was prohibited rested in large part on the argument that the terms of use were contractually binding on visitors to the site - if that were so, however, then the clause would take effect and Article 23 of the Brussels Regulation would confer exclusive jurisdiction on the English courts. Travelfusion was also in an awkward position - seeking to assert that the choice of law clause was effective while the remainder of the terms of use were not. As the court noted:
the circumstances giving rise to the issue in this case are highly unusual. The party who has produced the standard form containing a choice of jurisdiction clause is the one saying it does not apply. Equally the party denying that there is any contract at all is the one who is placing reliance on a clause which arises out of a contract alleged by its opponent but denied by it.
Could Travelfusion rely on the choice of law clause while simultaneously denying the existence of a contract? The court's conclusion was that it could. Three factors were important in this outcome. First, it would do no injustice to Ryanair to apply a choice of law clause which it itself had put forward. Secondly, if Ryanair were successful in its claim the choice of law clause would necessarily be contained in any contract. Thirdly, the alternative would be wastefully to litigate the same issue (whether a contract existed) twice - once at the jurisdiction stage and once again at the substantive hearing.

Consequently, the court accepted that the choice of law clause applied and as such Ryanair's action against Travelfusion was struck out. The case against Bravofly, however, remains.

From a practical perspective, this is certainly a cautionary tale for internet businesses - don't assert a choice of law in your website terms of use unless you're happy for it to apply to all claims that might arise out of the use of the website.

(Ryanair's terms of use, incidentally, seem to have been amended since the start of this case in order to head off this type of defence. The current terms of use state "It is a condition precedent to the use of the Ryanair website, including access to information relating to flight details, costs etc., that any such party submits to the sole and exclusive jurisdiction of the Courts of the Republic of Ireland and to the application of the law in that jurisdiction, including any party accessing such information or facilities on their own behalf or on behalf of others.")

Sunday, March 01, 2009

The case against an Irish Internet Death Penalty

I've written a short piece for today's Sunday Business Post on the implications of the Eircom / IRMA deal for Irish internet users. Unfortunately the Business Post is no longer updating its online content until late on Sunday (in a move to drive sales of the dead tree version?) so you can't see it there yet. In the meantime, here's the story as it was submitted:
Time to oppose an Irish Internet Death Penalty

Banning someone from internet use is a draconian punishment. In an era where internet access is increasingly essential – whether to send an email, look for a job, or book a flight – to deprive a person of this basic right is to seriously disrupt their daily life. In fact, an internet ban is such a sanction that the Irish courts have only ever imposed this punishment in extreme cases involving child pornography.

Yet in a private deal between Eircom and the music industry – a deal which the music industry is now trying to force on other Irish internet service providers – internet bans may become commonplace. The deal has been called “three strikes and you’re out” but it might better be called “three accusations and you’re out” as there would be no trial, no evidence held up to court scrutiny and no right of appeal. Instead, once the music industry makes three allegations that a particular internet user is sharing music then Eircom will disconnect that user, applying what’s often called an internet death penalty while acting as judge, jury and executioner.

What might this deal mean for the Irish internet? We can certainly expect users to be wrongfully accused. The company which the music industry previously used to identify filesharers – MediaSentry – has a track record of false accusations and was recently found to be operating illegally in several US states. As a result, the music industry has recently dumped MediaSentry and turned to Danish firm Dtecnet – but the inherent unreliability of this process remains.

Ironically, Eircom users will be particularly vulnerable to false accusations. In 2007 Eircom supplied up to 250,000 customers with wireless modems whose passwords were insecure. This means that a neighbour or passer by could easily use their broadband without their permission. Should they face an internet ban for the actions of somebody piggybacking on their wireless?

This reflects a broader problem where innocent third parties will be affected. Internet connections are not generally unique to an individual. Instead they’re shared – amongst families and flatmates for example. But three accusations will mean the connection will be shut off for every user so that others will suffer based on the alleged wrongdoing of another.

The deal is also undemocratic. The European Parliament has recently rejected a scheme to disconnect users based on mere accusations. In the United Kingdom similar proposals were ultimately rejected after public consultations and open debate. Here, however, the music industry is trying to foist this system on ISPs in a private deal while bypassing scrutiny by the Oireachtas, the Department of Communications and the democratic process.

In another part of this deal, as well as disconnecting users the music industry also wants Irish ISPs to impose a second type of internet death penalty, by preventing Irish users from reading certain websites. This time there is pretence of legal cover, in that the obligation would be to block websites only where a court order is granted – but the music industry has threatened to sue any ISP which opposes such an order, meaning that any court will hear only one side of the story. The result, if this scheme is allowed to proceed, will be to make ISPs responsible for censoring what their users can view on the internet.

If this precedent is set for the music industry, expect others to follow soon after. The publishing industry, for example, might target Google’s Book Search project which it has claimed infringes copyright. The Church of Scientology already has a track record of trying to silence criticism by claiming that its copyright is infringed by certain sites. Diebold – a US manufacturer of electronic voting machines – has been found by the US courts to have abused copyright law to shut down internet sites in order to conceal flaws in its technology. If Irish ISPs become internet censors then similar plaintiffs can be expected to try their luck here.

Quite apart from civil liberties concerns, there are also commercial costs. If this deal is allowed to proceed it will harm Ireland’s reputation as an internet-friendly country. By requiring companies to police the actions of their users and censor what they can see – a duty which they are not subject to in other jurisdictions such as the United States – it will drive up costs (for both companies and users), harm inward investment and encourage technology firms to relocate elsewhere.

In short, this deal is an unacceptable threat to Irish internet users and businesses. Fortunately, so far only Eircom has signed up. Other ISPs are still considering whether to cave in to the threats of the music industry. There is still time for them to do the right thing and say no to a privatised internet death penalty.

TJ McIntyre is a solicitor, Lecturer in Law in University College Dublin and chairman of Digital Rights Ireland.

Edited to add: The piece is now online.

Tuesday, February 10, 2009

ECJ upholds Data Retention Directive

The big news of the day is that the European Court of Justice has upheld the Data Retention Directive against the challenge by the Irish Government in Ireland v. Parliament and Council where it was claimed that it was adopted on the wrong legal basis. The decision doesn't consider whether the Directive is in breach of fundamental rights, and the Digital Rights Ireland action on that basis will continue. More once I've had a chance to read the full decision.

Wednesday, February 04, 2009

ECHR expands scope of privacy rights?

OUT-LAW has details of a recent European Court of Human Rights decision which may push out the boundaries of privacy rights - in particular by finding a violation based on the taking of a photograph alone (without any publication). The facts in Reklos and Davourlis v. Greece were:
The applicants, Dimitrios Reklos and Vassiliki Davourli, are Greek nationals who were born in 1964 and 1967 respectively and live in Athens. They are the parents of Anastasios Reklos, who was born on 31 March 1997 in a private clinic. Immediately after birth, the baby was placed in a sterile unit to which only medical staff had access.

As part of the photography service offered to clients, two photographs of the new-born baby, viewed face on, were taken by a professional photographer. The parents objected to this intrusion into the sterile environment without their prior consent.

On 25 August 1997, following the clinic’s refusal to hand over the negatives of the photographs to them, the applicants brought an action for damages before the Athens Court of First Instance. The court dismissed the action as unfounded.

In September 1998 the child’s parents appealed unsuccessfully against that decision. In August 2002 they lodged an appeal on points of law, submitting that the court rulings had infringed the right “to dignity” and “to protection of private life”, and stressing the potential dangers for disabled children.

On 8 July 2004 the Court of Cassation dismissed the appeal on points of law on the ground that it was too vague. (Facts taken from the ECHR press release - judgment in English not yet available.)
The ECHR agreed with the parents, holding:
The Court reiterated that the concept of private life was a broad one which encompassed the right to identity. It stressed that a person’s image revealed his or her unique characteristics and constituted one of the chief attributes of his or her personality. The Court added that effective protection of the right to control one’s image presupposed, in the present circumstances, obtaining the consent of the person concerned when the picture was being taken and not just when it came to possible publication.

The Court observed that, since he was a minor, Anastasios’s right to protection of his image had been in the hands of his parents. Their consent had not been sought at any point, not even with regard to the keeping of the negatives, to which they objected. The Court noted that the negatives could have been used at a later date against the wishes of those concerned.

The Court concluded that the Greek courts had not taken sufficient steps to guarantee Anastasios’s right to protection of his private life, in breach of Article 8. (Emphasis added.)
The portions in bold are significant: unlike earlier caselaw on photography / CCTV (such as von Hannover v. Germany or Peck v. United Kingdom) the Court identified the taking of the photograph itself as a violation irrespective of whether it was subsequently published or otherwise made public. This is - as Rosemary Jay points out in the OUT-LAW post - consistent with the approach taken in the UK DNA Database case last December (S and Marper v. United Kingdom) where the focus was on the gathering and storage of personal information rather than its subsequent use. As such, it is potentially important for the argument that data retention is itself a violation of Article 8, whether or not any further use is made of the retained data.

Thursday, January 29, 2009

"Three strikes" for Ireland - Eircom, music industry settle filtering case

The big news of the day in Ireland is that Eircom and the music industry have settled the case in which the music industry had demanded that Eircom monitor users' connections to block peer to peer filesharing (background here). Instead the industry has dropped the action on condition that Eircom introduce a "three strikes" system where users accused of filesharing by the music industry will be disconnected after two warning letters. According to Eircom it has agreed to:
1) inform its broadband subscribers that the subscribers IP address has been detected infringing copyright and

2) warn the subscriber that unless the infringement ceases the subscriber will be disconnected and

3) in default of compliance by the subscriber with the warning it will disconnect the subscriber
More from Digital Rights Ireland | EFF | ars technica | Boing Boing | Daithi. Oisin, commenting on Lex Ferenda, makes some interesting points which in the spirit of the litigation I'm shamelessly going to copy (though I'm not sure that I agree that Eircom will need to change their terms of use - the existing policy is already drafted to allow termination for almost any infraction):
What’s probably going to happen is that this whole issue is going to shift from being an IP/regulatory law one to being a contract/ consumer protection law one. Two points spring to mind.

First, to put this settlement into practice Eircom will have to modify its terms of service for all its current customers (without giving any legal consideration for a unilateral modification of a contract) which could pose considerable enforceability problems. Moreover, to properly incorporate the ‘three strikes and your out’ rule into its contracts Eircom is probably going to have to draw this new provision to the attention of its subscribers (so we may, indirectly, get to figure out what the terms of settlement were).

Second, and more interestingly, if, and when, Eircom seeks to terminate someone’s service, we may finally get some litigation as to whether or not these often unfair, impenetrable user agreements are actually enforceable or not. We’ll finally get to see if the Unfair Terms Directive, along with all the old common law and equity cases on enforcing one-sided terms that weren’t negotiated or drawn to the parties attention have any bearing on user agreements.
My take? This isn't really a win for the music industry. They were clearly hoping for an outright win requiring all ISPs to filter and setting a precedent in a common law jurisdiction to match SABAM v. Tiscali. Instead they've merely achieved an agreement with one ISP - albeit the largest - which doesn't go any further than they might have been able to achieve by negotiation in the first place. As Ronan Lupton points out the agreement is not enforceable against the rest of the industry, and it is debatable whether other ISPs will show any appetite to come on board. Moreover, if three strikes is challenged as Oisin suggests then it will receive much less judicial deference than if it had been adopted as part of an industry wide deal with explicit government support.

It is, though, a loss for the user. The three strikes process in this case is procedurally
unfair and represents an extreme model largely rejected elsewhere.

Tuesday, January 27, 2009

Blogger who didn't delete comment can't sue over it

OUT-LAW has a very interesting application of the rule that one cannot sue for libel in respect of a publication to which one consents:
Christopher Carrie is the author of a self-published book in which he claims to have been sexually abused by the son of writer JRR Tolkien, Father John Tolkien. John Tolkien, who was a priest, died in 2003.

Carrie set up a blog on 5th February 2007 and published a post under a pseudonym on 6th February, promoting his website and his book, which could be downloaded from there for free.

The court heard that JRR Tolkien's great grandson Royd Tolkien had posted a comment on the site claiming that Carrie was a fraudster who had tried to defraud the Catholic Church and the Tolkien family and had admitted to lying about sexual abuse to extract money from the church.

Carrie denied the claims via his pseudonym on the site, and sued Tolkien, claiming that the remarks were defamatory.

Carrie did not remove the remarks, though, even though the Court heard that he had seen them four-and-a-half hours after they were posted. The remarks are still online.

Tolkien argued that this meant that Carrie consented to the publication of the comments, and the High Court agreed. Mr Justice Eady granted summary judgment in favour of Tolkien.

"No explanation was offered for [Carrie] having taken no steps to delete it until his witness statement of 18 November 2008 was served," said the ruling. "The explanation given, however, of putting the words 'in context' does not in any way detract from the validity of a defence of authorisation or acquiescence. The fact remains that he could have removed it at any time over the last 22 months."
Full judgment here.

What's it all about?

Here's a word cloud from the excellent Wordle visualising recent posts to this blog:

Monday, January 19, 2009

Data Protection Review Group Announced

The Department of Justice has today announced the creation of a Data Protection Review Group on breaches of data protection. The terms of reference are:
a. Legal issues

i. Consider whether Irish Data Protection legislation needs to be amended to deal with data breaches.
ii. Assess the effectiveness of existing legislation in this context, including the impact of mandatory reporting legislation where it has been introduced.
iii. Assess the likely impact of the scope and timing of the forthcoming ePrivacy Directive and next EU Data Protection directive and other relevant international legislative developments.
iv. Describe the range of options in existing legislation within EU and with competing non EU states.
v. Consider the potential formats of mandatory reporting.
vi. Consider the role and level of penalties in any mandatory regime.

b. Technical issues


i. Definition of "breach" in the context of how organisations' use of technology is changing.
ii. Assessment of the assortment of devices and locations holding data now.
iii. Assessment of whether the same mechanisms should apply to paper and electronic media in any suggested change.
iv. Attempt to foresee unintended consequences in the light of the rapid evolution of technology and business practices.

c. Regulatory issues

i. Assess the prevalence of the data breach problem and level of existing reports.
ii. Assess any empirical evidence that Data Protection legislation informs industrial location decisions.
iii. Consider whether any change bear on Public and Private sectors equally.
iv. Assess how to establish the threshold of seriousness - in some cases a very small number of records could potentially cause substantial harm.
v. Balance the potential effectiveness of any proposed change against increasing the costs of doing business in Ireland - the Group should, insofar as possible, ensure that its deliberations equate to a Regulatory Impact Analysis.

The members of the group are:
Chairman: Mr. Eddie Sullivan (former Secretary General Department of Finance), Mr. Billy Hawkes, Data Protection Commissioner, Professor Robert Clark (School of Law, UCD), Ms. Isolde Goggin (former Chair of Comreg and expert on Regulatory Impact Assessment), Mr. Alec Dolan & Ms. Noreen Walsh (Department of Justice, Equality and Law Reform, Mr. Dave Ring (CMOD, Department of Finance), Mr. Tony McGrath (Department of Enterprise, Trade and Employment), Mr. Paul Carroll (Department of Social and Family Affairs) and Mr. Roger O'Connor (Department of Communications, Marine and Natural Resources).

The decision to look at data breaches - and in particular mandatory reporting - was made in October of last year after parliamentary questions revealed that the government was losing at least one electronic device per week, and that the vast majority of devices were not encrypted.

Submissions to the group should be sent to dataprotectionreview@justice.ie by March 1st.

Thursday, January 15, 2009

The Music Industry v. Eircom - Let Battle Commence!

The trial started today in the case being brought by the EMI, Sony, Warner and Universal against Eircom, in which the music industry is demanding that Eircom put in place a filtering system to block peer to peer downloads. The case is being heard in the High Court before Charleton J. under the record number 2008/1601P EMI RECORDS IRELAND LTD & ORS V EIRCOM LTD. It's listed for hearing for four weeks (and will be in Court 7 should you be passing the Four Courts and interested in observing some of the argument). For the argument that the plaintiffs' case represents a threat to privacy and freedom of expression on the internet see this Digital Rights Ireland post.

Update (16.01.08): The Irish Times has coverage of the first day of hearings. I was rather amused by this internal email from 2001:
"We need to reach a decision on how we are going to handle this," the e-mail said. "PS: 'piracy' is a loaded term. Could we say 'sharing' – 'piracy' implies there’s something wrong with it.

"Think of it as helping the health and good living of rich cocaine-sniffing rock stars by leaving them with less free money to spend on sex and drugs."
In a separate story, the Irish Times also reveals claims by the music industry that their campaign of litigation directly against individual uploaders "had cost the companies some €600,000 and secured compensation of only €70,000".

Tuesday, January 13, 2009

ComReg to Regulate .ie ccTLD

Important news for the Irish internet with the announcement that Comreg has completed its consultation process and now proposes to introduce a new framework for regulation of the .ie top level domain. The press release summarises the changes as follows:
- ComReg will, by way of regulation, appoint IEDR as the authority authorised to register .ie domain names in accordance with Section 32(4)(a) of the Act of 2007,
- IEDR will set up and maintain a Policy Advisory Committee (PAC) representative of all stakeholders with a focus on more transparent policy development,
- IEDR will continue to adopt the "managed approach" to .ie registrations to ensure continued protection for .ie domain name holders and consumers,
- ComReg will implement a monitoring framework and will participate in the PAC to keep abreast of activities in the marketplace,
- Further regulatory measures may be considered in the future, as warranted.
Daithi has an excellent post discussing the ComReg proposals and their background, which I won't attempt to follow until I've had a chance to look at the proposals in more detail - but I can't help wondering whether this will now mean that the IEDR may be subject to judicial review.

Sunday, January 11, 2009

An Irish "Digital Legal Services Centre"?

The Irish Institute of European Affairs has a strong track record of hosting and promoting debate on issues around technology and law. Recent speakers have included Jonathan Zittrain, Bruce Schneier, Viviane Reding, Peter Fleischer, and Larry Sanger.

Now the IIEA has launched a report - The Next Leap: Competitive Ireland in the Digital Era (PDF) - which is full of interesting ideas aimed towards promoting Ireland as a "software and services hub".

One that struck me was the notion of establishing an Irish Digital Legal Services Centre. This, so the suggestion goes, would be:
an IFSC type development from which services such as intellectual property, rights clearance, payments, data protection, retention & privacy etc. could be provided for digital firms operating within the EMEA region.
This is a particularly good idea and in many ways is the next logical step from the early approach which the Irish government took towards promoting Ireland as an e-commerce location (particularly in the run up to the adoption of the Electronic Commerce Act 2000). It would also build on the expertise which is already developing here in servicing the Irish branches of firms such as PayPal, Ebay, Google and Microsoft.

So what could be done to promote this idea?

For a start, we would need government recognition of the importance of the Data Protection Commissioner. If Ireland is to be a credible location for online businesses it needs a data protection system which is capable of being the de facto lead regulator for multinational operations. Recent government moves (by decentralising the office to Portarlington resulting in the loss of staff and expertise and by the abortive proposals to merge the office with entirely dissimilar agencies) suggest that the government has little understanding of the importance of this role.

We would also need to see a reversal of policy in relation to data retention. The Department of Communications has repeatedly warned that government policy here will mean imposing increased costs on Irish business and reducing competitiveness - particularly where there are no provisions for cost reimbursement - but the Department of Justice has ploughed on regardless to achieve the largely mythical benefits of data retention.

Conversely, the Department of Justice has also ignored areas of Irish law where change is essential and could be achieved at relatively low cost. As I've said for a while now, Irish law on computer crime is badly in need of reform. Areas such as interception of online communications, access to stored communications and denial of service attacks are essentially unregulated - giving little protection to online businesses. Legislation in this area is long overdue and would help to promote Irish attractiveness for online business.

Another area which would benefit from (relatively cheap and easy) reform is Internet gaming. Ireland is already a hub of internet gaming sites, but still operates on the basis of laws which are obscure and outdated. The Department of Justice has already - to its credit - dealt with some of the issues involved in the report "Regulating Gaming in Ireland", but more needs to be done. It would be undesirable if the political dispute in relation to fixed odds betting terminals were to hold up reform of online gaming.

Reforming the possible liability of online intermediaries generally should also be a priority. Ireland has adopted a barebones implementation of the Electronic Commerce Directive, creating only the mandatory exemptions from liability in respect of hosting, mere conduits and caching. This compares with other jurisdictions which have created immunities for e.g. search engines and content aggregators. This narrow approach is something which worries intermediaries (UK link but Irish law is very similar) and there is a strong argument to be made for extending the hosting notice and takedown model to other intermediaries also. Failure to do so will undermine the desirability of Ireland as a location for such services.

Neil Leyden has some interesting comments / proposals in a similar vein here and here.

Saturday, January 10, 2009

Data Protection Commissioner may prosecute for spam without seeking negotiated settlement - High Court

As we've seen before ("How to be sued by space cadets") Realm Communications has been trying to stymie prosecutions being brought against it for spam. Their claim has been that the Data Protection Commissioner is under a statutory duty to seek an amicable resolution before resorting to the heavy guns of a criminal prosecution.

In the recent statutory instrument amending data protection law the Minister sought to preempt this argument for future cases, by including a provision stating that:
If of the opinion that the circumstances relating to a complaint investigated under Regulation 17 involve the commission of an offence under these Regulations, the Commissioner may bring and prosecute proceedings for the offence without attempting to bring about an amicable resolution of the complaint.
But this still left the position in doubt in respect of offences committed and prosecutions commenced before this change.

The High Court has now rejected the argument that an amicable resolution must be sought, McCarthy J. holding (according to the Irish Times report) that "the absence of resolution attempts did not erase the fact that regulations were breached". This is an unsurprising result - the legislation certainly doesn't expressly provide that there must be an attempt at settlement, and while it might be best practice to do so, a strict duty would tie the hands of the DPC (especially when dealing with repeat offenders) and would undermine the effectiveness of the criminal penalty. But though the result might have been predictable the ruling is still useful, particularly as it clarifies the position in respect of other pending prosecutions. (Edited to add: full judgment now available here.)

Wednesday, January 07, 2009

Danish censorship list leaked

Another internet censorship story which didn't get the attention it deserved over Christmas was the revelation that the blacklist operated by the Danish child pornography filtering system - all 3863 blocked URLs - was leaked on December 23 and is available in full online.

If nothing else, this (in conjunction with the Thai leak) vividly illustrates one key criticism of any internet filtering system - that the list of blocked content will inevitably leak and so facilitate access to the supposedly blocked content.

A note of caution for bloggers - the Danish list is reported to contain links to child pornography sites, meaning that linking to the list might itself be an offence under section 5 of the Child Trafficking and Pornography Act 1998. That section makes it a criminal offence to "knowingly [publish] or [distribute] any advertisement likely to be understood as conveying that ... any other person produces, distributes, prints, publishes, imports, exports, sells or shows any child pornography". Legal opinion in the UK (in relation to their similar Protection of Children Act 1978) has been that domain names and URLs might themselves constitute such illegal advertisements.

Monday, January 05, 2009

Thai censorship list leaked: RTÉ News blocked

Thailand's Ministry of Information and Communication Technology operates a secret internet censorship system, blocking access to websites deemed unsuitable for the Thai people. The list of blocked websites has now been leaked, and makes for interesting reading. Doubtless Thais will be glad to know that they are being protected from such evils as the Economist , Charlie Chaplin and Hillary Clinton's campaign videos.

Irish readers will be interested to note that one of the banned pages is from RTÉ News, even though that page merely discusses Thai blocking of YouTube and does not itself contain any content that could remotely be considered offensive.